Karman Space & Defense Logo

Karman Space & Defense

Senior Cybersecurity Engineer

Posted One Month Ago
Be an Early Applicant
In-Office
Huntington Beach, CA, USA
130K-165K Annually
Senior level
In-Office
Huntington Beach, CA, USA
130K-165K Annually
Senior level
Engineers identity security, privileged access, vulnerability management, endpoint and cloud security across a multi-site aerospace and defense environment. The role administers Microsoft security tools, investigates alerts, coordinates remediation, validates technical controls, supports CMMC and NIST assessments, maintains evidence and procedures, and reviews technology projects for security risks. It also contributes to incident response, audit remediation, M&A activities, automation, and mentoring across IT and security teams.
The summary above was generated by AI

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role strengthens identity security, privileged access, vulnerability management, and technical remediation across Karman’s multi-site environment. You will engineer and continuously improve security controls across Microsoft platforms, endpoints, servers, cloud environments, site technologies, and specialized assets. Working closely with Infrastructure, Business Systems, site teams, and service providers, you will ensure clear ownership, reliable evidence, and sustainable remediation that supports regulated aerospace and defense requirements.

Responsibilities

  • Engineers and improves identity security across Active Directory, Microsoft Entra ID, Microsoft 365 GCC High, cloud platforms, business applications, and related services.
  • Strengthens identity lifecycle processes, access provisioning, privileged access, multifactor authentication (MFA), conditional access, role-based access control, and non-human identity protections.
  • Operates and matures enterprise vulnerability management, ensuring authenticated scanning, asset coverage, data quality, prioritization, remediation coordination, and validated closure.
  • Partners with Infrastructure to enhance endpoint, server, and cloud security through patching, encryption, device management, configuration baselines, detection capabilities, and Microsoft security tools.
  • Reviews new Microsoft 365, Software‑as‑a‑Service (SaaS), cloud, and AI-enabled capabilities for identity, access, logging, and data-handling requirements.
  • Administers assigned security tools and investigates identity, endpoint, email-security, vulnerability, and logging alerts; supports containment, evidence preservation, and post-incident hardening.
  • Implements, validates, and documents technical controls supporting CMMC Level 2, NIST SP 800‑171, DFARS, Controlled Unclassified Information (CUI), and Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC).
  • Supports technical remediation of assessment findings, audit gaps, Plans of Action and Milestones (POA\&Ms), and control failures and participates in walkthroughs, reviews, and assessments.
  • Reviews technology projects, integrations, deployments, SaaS services, vendor solutions, and M\&A activities for identity, vulnerability, endpoint, and data-exposure risks.
  • Maintains technical procedures, configurations, remediation guides, metrics, and automation opportunities and mentors IT and security teams to strengthen operating capability.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field; equivalent relevant experience may be considered.
  • 7+ years of progressive experience in cybersecurity engineering, identity and access management, vulnerability management, endpoint security, infrastructure security, or related roles.
  • Hands-on experience with Active Directory, Microsoft Entra ID, Microsoft 365, MFA, conditional access, single sign-on (SSO), privileged access, identity lifecycle processes, and non-human identities.
  • Experience operating enterprise vulnerability‑management tools, establishing scan coverage, prioritizing risk, coordinating remediation, and validating closure.
  • Experience with endpoint protection, hardening, patching, device compliance, security monitoring, and the Microsoft security ecosystem.
  • Working knowledge of Windows endpoint and server security, cloud and network security, segmentation, secure configuration, logging, and incident response.
  • Experience producing technical control evidence and supporting audits, assessments, or regulated control environments.
  • Strong troubleshooting, documentation, communication, and cross-functional coordination skills in a fast-paced, multi-site environment.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Direct experience with CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, GCC High, or export‑controlled environments.
  • Experience with Microsoft 365 GCC High and tools such as Defender, Intune, Entra ID, Purview, Sentinel, Tenable, Qualys, Rapid7, or Defender Vulnerability Management.
  • Experience with privileged access management, password vaulting, security information and event management (SIEM), endpoint detection and response (EDR), email security, and security orchestration.
  • Experience with mergers and acquisitions (M\&A), site onboarding, identity consolidation, endpoint standardization, and post-acquisition remediation.
  • Familiarity with firewalls, virtual private networks (VPN), network segmentation, Zero Trust, Center for Internet Security (CIS) benchmarks, specialized assets, and compensating‑control design.
  • Security+, Cybersecurity Analyst (CySA+), Systems Security Certified Practitioner (SSCP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Security Essentials Certification (GSEC), GIAC Certified Incident Handler (GCIH), Microsoft Security, Azure Security Engineer, or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD\&D insurance
  • Short‑ and long‑term disability coverage
  • Tuition reimbursement

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.

HQ

Karman Space & Defense Huntington Beach, California, USA Office

5351 Argosy Ave, Huntington Beach, California, United States, 92649 1036

Similar Jobs

16 Days Ago
In-Office
103K-214K Annually
Senior level
103K-214K Annually
Senior level
Other • Utilities
Leads SOC and incident response process improvement, automation, analytics, and responsible AI adoption. Designs and documents threat response workflows, builds SOAR and AI integrations, governs use cases, develops reporting, and trains teams. Partners cross-functionally to deliver cybersecurity initiatives, improve response speed, reduce manual effort, and strengthen threat response capabilities.
Top Skills: APIsArtificial IntelligenceClaudeLarge Language ModelsMicrosoft SentinelPythonSecurity AutomationSIEMSoarSplunk
4 Hours Ago
In-Office or Remote
United States
100K-193K Annually
Senior level
100K-193K Annually
Senior level
Automotive
Designs, develops, and maintains GCP-based security data pipelines and data products. Builds data quality and auditing frameworks, integrates security tools through APIs, optimizes BigQuery schemas and costs, and deploys automated ETL/ELT workflows using Python, SQL, and GCP services. Partners with security teams to deliver reporting views and dashboards. Cribl Stream experience is preferred for processing, enriching, routing, and reducing security telemetry and logs.
Top Skills: APIsBigQueryCloud FunctionsCloud RunCloud SchedulerCloud StorageCribl StreamDataflowDataplexGoogle Cloud Platform (Gcp)Pub/SubPythonSQLTrend Micro
22 Minutes Ago
In-Office
153K-204K Annually
Senior level
153K-204K Annually
Senior level
Cloud • Information Technology • Machine Learning
Build and operate full-stack applications and AI-facing features for CoreWeave’s internal data platform. Responsibilities include developing TypeScript, React, Next.js, and Python services; designing APIs and relational data models; integrating analytical data platforms; deploying on Kubernetes; and owning production reliability, testing, observability, and on-call support. The role also involves collaborating with non-engineers to define processes, shipping LLM-backed applications, and evaluating AI output quality.
Top Skills: BigQueryCi/CdDelta LakeDockerHelmHudiIcebergKafkaKubernetesLanggraphNext.JsPostgresPythonReactSnowflakeSparkSQLStarrocksTypescript

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account